CVE-2025-15568Disclosure(tp-link / archer_axe75)

LOWCVSS 8.0 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch tp-link archer_axe75 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A command injection vulnerability was identified in the web module of Archer AXE75 v1.6/v1.0 router. An authenticated attacker with adjacent-network access may be able to perform remote code execution (RCE) when the router is configured with sysmode=ap. Successful exploitation results in root-level privileges and impacts confidentiality, integrity and availability of the device. This issue affects Archer AXE75 v1.6/v1.0: through 1.3.2 Build 20250107.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • archer_axe75
  • archer_axe75_firmware

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-09); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
archer_axe75archer_axe75_firmware

3 versions affected across 2 products

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-09: 2Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-03-11: 1Technical Details · 2026-03-09: 2Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 103-0903-1003-11
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-092
Disclosure2
2026-03-101
Patch1
2026-03-111
Patch1
Full discourse4 posts
  • Gray Hats@the_yellow_fall
    Patch

    A critical 8.5 CVSS command injection flaw (CVE-2025-15568) in TP-Link Archer AXE75 routers allows complete root-level network takeover. Patch immediately. #TPLink #ArcherAXE75 #CVE #InfoSec #CommandInjection #RouterSecurity #PatchAlert #Vulnerability https://securityonline.info/home-network-alert-tp-link-patches-rce-vulnerability-in-archer-axe75-routers/

    Post summary

    The TP‑Link Archer AXE75 routers suffer a critical command injection flaw (CVE‑2025‑15568) with an 8.5 CVSS score that enables root‑level takeover; users are urged to apply the vendor‑issued patch immediately.

    04030396
    10.6K followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    📌TP-Link تعالج ثغرة RCE حرجة في موجهات Archer AXE75 أصدرت TP-Link تحذيرًا أمنيًا عاجلاً لمستخدمي موجهات Archer AXE75، بسبب اكتشاف ثغرة (Command Injection) مُسجلة تحت CVE-2025-15568. تُمكّن هذه الثغرة المهاجمين من تنفيذ (RCE) والسيطرة الكاملة على الأجهزة المستهدفة، مما يشكل تهديدًا مباشرًا لأمن الشبكات المنزلية. استجابت الشركة بإصدار تحديث أمني لمعالجة هذا العيب. 🔗 للمزيد: https://securityonline.info/home-network-alert-tp-link-patches-rce-vulnerability-in-archer-axe75-routers/

    Post summary

    TP‑Link has issued a patch for CVE‑2025‑15568, a command‑injection RCE flaw affecting Archer AXE75 routers; the post provides technical details but no evidence of active exploitation or exploit code.

    00020320
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-15568 A command injection vulnerability was identified in the web module of Archer AXE75 v1.6/v1.0 router. An authenticated attacker with adjacent-network access may be ab… https://www.cve.org/CVERecord?id=CVE-2025-15568

    Post summary

    A command injection vulnerability (CVE-2025-15568) was identified in the Archer AXE75 v1.6/v1.0 router's web module, requiring an authenticated attacker with adjacent-network access.

    0000088
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-15568 Command Injection in Archer AXE75 Router Enables Authenticated Remote Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-15568

    Post summary

    The brief notice announces a newly identified CVE-2025-15568 involving command injection that enables authenticated remote code execution on Archer AXE75 routers, focusing on the vulnerability's exposure rather than exploitation details or mitigation.

    0000047
    4.0K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
HWtp-linkarcher_axe751.0--
HWtp-linkarcher_axe751.6--
OStp-linkarcher_axe75_firmware---
OStp-linkarcher_axe75_firmware1.3.2--
OStp-linkarcher_axe75_firmware1.3.2--

Explore more